Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network engineer is configuring a Cisco ASA firewall with a site-to-site VPN to a remote peer. The engineer wants to ensure that only specific subnets are encrypted and that traffic from other subnets is not sent through the tunnel. Which configuration element defines the traffic that will be protected by the VPN?

⚠ Common exam trap

The trap here is assuming that the tunnel-group or IKEv2 proposals define the traffic to be encrypted, when in fact the crypto ACL is the sole determinant of interesting traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The crypto ACL (access list) referenced in the crypto map.

In a site-to-site VPN on Cisco ASA, the crypto ACL (also called the interesting traffic ACL) defines which source and destination subnets are encrypted and sent through the tunnel. Only traffic matching this ACL is protected; other traffic is sent in clear text or dropped based on interface ACLs. The tunnel-group, group-policy, and IKEv2 proposals handle peer authentication and encryption parameters, but not traffic selection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IKEv2 proposal and policy settings.

    Why it's wrong here

    IKEv2 proposals and policies define the encryption, integrity, and authentication algorithms used during Phase 1 and Phase 2 negotiations. They do not specify which traffic is encrypted. They are essential for establishing the VPN but do not control the selection of subnets. Thus, they do not fulfill the requirement of defining protected traffic.

  • ✓

    The crypto ACL (access list) referenced in the crypto map.

    Why this is correct

    The crypto ACL defines the interesting traffic that will be encrypted and sent through the VPN tunnel. It specifies source and destination subnets that are permitted, and only matching traffic is protected. On Cisco ASA, this ACL is referenced in the crypto map entry. It is the correct element to control which subnets are encrypted, as required by the scenario.

  • ✗

    The tunnel-group configuration for the remote peer.

    Why it's wrong here

    The tunnel-group defines parameters for the remote peer, such as pre-shared key, authentication method, and IKE policies. It does not specify which traffic is encrypted. While necessary for VPN establishment, it does not control the selection of subnets to protect. Therefore, it does not meet the requirement of defining protected traffic.

  • ✗

    The group-policy applied to the VPN connection.

    Why it's wrong here

    The group-policy defines user attributes and restrictions for VPN clients, such as split tunneling, DNS servers, and filtering. It does not determine which subnets are encrypted in a site-to-site VPN. It is used primarily for remote-access VPNs and does not define the traffic selectors for site-to-site tunnels.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.